Lire en français

Privacy Policy

Effective date: 16 September 2026 · Applies to the Explia mobile app (iOS and Android)

In short

  • Explia works without an account. We do not know who you are.
  • Your saved studies, followed topics, recent searches and settings stay on your phone. You can delete them at any time from Settings.
  • When you search or open a study, the app sends our server only what is needed to answer (the search text, article numbers, your language). Nothing is linked to you.
  • No advertising, no tracking tools, no cookies. The only measurement is anonymous and aggregate usage statistics (counts of screens and actions, such as searches or summaries — no identifier, no search text, no study title) sent to a statistics server we run; you can switch them off in Settings (section 7).
  • If you subscribe to Explia Plus, the purchase is handled by the App Store or Google Play and verified for us by RevenueCat under an anonymous identifier — still no account, no name, no e-mail (section 7).
  • Please do not type personal information (names, dates of birth, medical records…) into the search field.

1. Who is responsible

Explia is published by Stéphane Hirondelle, independent publisher (postal address available on request at the contact e-mail below) (“we”, “us”), who acts as the data controller for the very limited processing described here. You can write to us at contact@nutriflow-app.net.

This policy covers the Explia app only. Websites you open from the app (PubMed, PubMed Central, publishers’ sites) have their own privacy policies.

2. What Explia does not do

If this ever changes, we will update this policy and the app-store listings before releasing the change.

3. Information stored on your device

To work, the app keeps a few things on your phone, in the app’s private storage (the system “preferences” store of iOS and Android):

Explia never uploads this information anywhere: it is not synchronised, and we cannot see it. It may be included in the backups of your phone that you set up with Apple or Google, which are governed by their terms.

Weekly alerts. If you turn them on in Settings, the weekly “new studies” notification is computed on your device from your followed topics: in the background, the app sends the same anonymous count requests as the “new studies” counters of the home screen (see section 4), and the notification is built locally. Nothing else is sent, and no notification service or push token is involved.

Deleting it: in the app, open Settings and tap “Delete all my data”. Saved studies, followed topics and recent searches are removed from the device (settings and the free-trial counter are kept). Uninstalling the app removes everything, settings included.

4. What is sent to our server

To search PubMed and produce plain-language summaries, the app talks to a server we operate (a “serverless function” hosted by Supabase, see section 7). Each request carries only what is needed to answer it:

When you…the request contains
search a topicthe PubMed search query, your filters (study types, humans only, period, free full text, sort order) and the page number
type a question in your own wordsthe text of the question and your language, so it can be turned into a PubMed query
open a study or a list of resultsthe PubMed identifiers (PMIDs) of the articles, and your language
read a plain-language summarythe PMID of the article and your language
open the home screen with followed topicsthe followed queries and the date of your last visit, to count new studies

Requests are not linked to a person. There is no account, no user or device identifier and no name in them. We keep no log of “who searched what”. Where the server needs a key to remember an answer (a cache), the key is a hash computed with a secret salt — never the text itself.

Connection data. Like any online service, our hosting provider has to receive your IP address to route the connection to our server and back, and may keep short-lived technical logs to operate and secure its platform. We do not store your IP address in clear (see section 5).

5. Daily fair-use limit

Plain-language summaries cost money to produce, so the server applies a daily limit per user and an overall daily limit. To count without identifying you, the server computes a hash of three things: a secret salt, the day, and the IP address of the connection. This hash cannot be turned back into an IP address, changes every day, is never stored in clear, and is used for counting only. The counters are deleted after 7 days.

6. What our server keeps (caches)

To answer faster and to limit calls to PubMed and to the AI service, the server keeps caches. None of them contains anything about you: the articles and summaries are the same for every user.

DataWhyKept for
PubMed search results (the list of article identifiers matching a query)Not to ask PubMed again for the same query2 days
PubMed article records (title, abstract, authors, journal, publication types…)To display them faster30 days
AI translations of questions into PubMed queries (the query itself and a very short restatement of the topic), stored under an anonymous hash — the text you typed is not storedNot to translate the same question twice90 days
Plain-language summaries and translated titles, per article and languageTo show the same summary to everyone instantly and reduce AI costsAs long as the service runs
Fair-use counters (section 5)To apply the daily limits7 days

7. Third parties that help the app work

NCBI E-utilities — PubMed (U.S. National Library of Medicine)

Every study comes from PubMed, a database of the U.S. National Library of Medicine (NLM), part of the National Institutes of Health. To fetch studies, the following is sent to NCBI: the PubMed search terms, the article identifiers, a tool name (“lucida-app”) and a contact e-mail address of the publisher of Explia (ours, not yours), as NCBI requires from every application. Normally these calls are made by our server, so NCBI sees our server and not your phone. If our server cannot be reached, the app can query PubMed directly from your phone (without plain-language summaries); PubMed then sees your IP address, like any website you visit. NLM privacy policy: nlm.nih.gov/privacy.html.

Google Gemini API (Google LLC)

Our server uses Google’s Gemini models to (1) turn the question you typed into a PubMed query, (2) write the plain-language summary of a study, and (3) translate study titles. What is sent: the text of your question (for translation only); the English title, journal, year, publication types and abstract of the article being summarised; the titles to translate. Neither your IP address nor any identifier is sent. No personal data is meant to reach Google — this is why you must not type personal information into the search field. Google processes this content under its Gemini API terms: ai.google.dev/gemini-api/terms.

Supabase (Supabase, Inc.)

Supabase hosts our server function and its database, in the following region: us-east-1 (United States, AWS via Supabase). As the host, Supabase processes connection data (IP address) to deliver the service. Privacy policy: supabase.com/privacy.

RevenueCat (RevenueCat, Inc.) — Explia Plus subscription

Explia Plus, the optional subscription, is bought through the App Store (Apple) or Google Play (Google) under the store’s own terms and privacy policy: the store handles your payment details, and we never see them. To know whether a subscription is active, the app uses the RevenueCat SDK, which receives from the store the purchase receipt / transaction data (product bought, purchase and expiry dates, trial or renewal status, store country and currency) together with an anonymous identifier generated for your installation (a random string). RevenueCat processes this on our behalf, for the sole purpose of granting and restoring the subscription (“entitlement”) and of aggregate subscription statistics; it is retained for the life of the subscription and RevenueCat’s standard retention period afterwards. We never send RevenueCat your name, e-mail, phone number, advertising identifier, device identifiers, location or any attribute about you, and the anonymous identifier is not linked to anything else in the app (it does not travel with your searches). Privacy policy: revenuecat.com/privacy. Store-listing wording: on the App Store this appears as “Purchases — Purchase history, not linked to you”; on Google Play as “Purchase history, collected, not shared”.

Usage statistics — Umami (self-hosted by the publisher)

To know how the app is used as a whole — how many searches, summaries, saved studies or subscriptions per day, which screens are used — the app sends anonymous, aggregate counts to a statistics server we operate ourselves (the open-source software Umami, on a server rented by the publisher; no third-party analytics company is involved). Each message contains only: the name of the event (for example “search”, “summary_shown”, “save”), a handful of fixed labels drawn from a closed list (the app language, the screen family such as “/theme” or “/article”, a result-count bucket such as “13–100”, the reliability level of a study, an error code, the subscription plan bought), the screen size, and an identifier of the app itself. It never contains the text you type, the title or identifier of a study, a device identifier, a user identifier, an advertising identifier, your location, or your name. Like any web server, the statistics server sees your IP address to receive the message; it uses it, together with the browser signature, to build a short-lived hash that lets it count how many distinct devices used the app, and to derive an approximate location (country / region), then does not keep the IP address itself. We cannot recognise you from these statistics, nor link them to your searches. You can turn them off at any time in Settings → “Anonymous usage statistics”; nothing is sent while they are off. Store-listing wording: on the App Store, “Usage Data — Product Interaction, not linked to you”; on Google Play, “App activity — App interactions, collected, not shared, not linked to you”.

Websites you open, and sharing

Links to PubMed, PubMed Central (free full text) and publishers’ pages open in your phone’s in-app browser; those sites’ own policies apply. When you share a study, your phone’s share sheet is used: what you share goes only where you send it.

The only processing that may concern personal data is the transient handling of your IP address to answer your requests and to apply the fair-use limit (sections 4 and 5), and, on the statistics server, to receive the anonymous usage counts (section 7). We rely on our legitimate interest in providing a working, secure and affordable service and in understanding how it is used as a whole (Article 6(1)(f) of the GDPR); the usage statistics can be switched off in Settings at any time. If you subscribe to Explia Plus, the purchase data described in section 7 is processed because it is necessary to perform the subscription contract with you (Article 6(1)(b)). Everything stored on your device stays under your control and is not processed by us.

9. Your rights

Under the GDPR and similar laws, you have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to lodge a complaint with a supervisory authority (in France, the CNIL: cnil.fr).

In practice, because we hold no data linked to you, there is nothing on our server that we could look up, correct or delete on your behalf: the hashed fair-use counters cannot be traced back to a person and disappear within 7 days. For an Explia Plus subscription, the purchase records held by RevenueCat are keyed by an anonymous identifier: write to us and we will explain how to find it on your device, then ask RevenueCat to delete those records; the store keeps its own records under its own policy. The information kept on your device is under your direct control (Settings → “Delete all my data”, or uninstall the app). For any question about your rights, write to contact@nutriflow-app.net.

10. International transfers

NCBI is located in the United States, and Google may process data in the United States or elsewhere. By design, what is sent to them contains no personal data: search terms about a topic, article identifiers, and the public text of scientific articles. Our own server and database are hosted by Supabase in the region indicated in section 7.

11. Children

Explia is not directed at children under 13 (or the applicable age in your country). We do not knowingly collect personal data from anyone, children included — the app collects no personal data at all. If you are a parent or guardian and believe your child has typed personal information into the app, please contact us.

12. Security

All connections use HTTPS. The server database is not reachable from the app or from the internet: only our server function can read or write it. API keys are never placed in web addresses. Cache keys are hashed with a secret salt. No system is perfectly secure, but the amount of information we hold is deliberately kept to a minimum.

13. Changes to this policy

We may update this policy, for example when we add a language or a feature. The date at the top tells you when it was last changed. Significant changes will be announced in the app or on its store listing before they take effect.

14. Contact

Questions, a mistake spotted, a request about your data: contact@nutriflow-app.net. You can also use “Contact us” in the app’s Settings.